Legal

Privacy Policy

Last updated: 31 July 2026

1. Who we are

This Privacy Policy explains how Pingly App Limited ("Pingly", "we", "us"), a company registered in Cyprus, collects, uses, and protects your personal data when you use the Pingly mobile application and the pingly.info website (together, the "Service").

Registered address: EDEN BEACH APARTMENTS, BLOCK 4, Office 112, 3035 Limassol, Cyprus. Company registration number: ΗΕ 446708. Contact for privacy questions: anna@pingly.info.

2. What data we collect

Pingly connects to third-party services you choose to link, and processes the following categories of personal data:

  • Account data: name, email address, and authentication tokens created when you sign up.
  • Email data: message metadata and content from Gmail and/or Outlook accounts you connect via OAuth, limited to what is needed to display and summarize your inbox.
  • Calendar data: event titles, times, participants, and locations from calendars you connect.
  • Task data: tasks and to-do items you create or import within Pingly.
  • Topics and Keywords: the interests, subjects, people, companies, teams, or terms you choose to have Pingly monitor for you.
  • News and content data: publicly available news articles, company announcements, and other public content retrieved and summarized based on your Topics and Keywords.
  • Usage and device data: app interactions, crash logs, device type, and operating system, used to keep the Service reliable and secure.
  • Location-derived data: an approximate location used only to localize weather and news content, where permitted by your device settings.
  • AI conversation data: prompts and responses exchanged with Pingly's AI assistant features.

3. How we use your data and our legal bases

We process personal data under the following legal bases available under the EU General Data Protection Regulation (GDPR):

  • Performance of a contract — to provide the core functionality you request, such as displaying your mail, calendar, and tasks in one place.
  • Consent — for connecting third-party mail/calendar accounts via OAuth, for optional AI features, and for any non-essential cookies or tracking on our website.
  • Legitimate interests — for service security, fraud prevention, and improving the Service, balanced against your rights and expectations.
  • Legal obligation — where we must retain or disclose data to comply with applicable law.

4. AI features and automated processing

Pingly uses artificial intelligence models to summarize messages, organize tasks, monitor your chosen Topics and Keywords across public news sources, and power conversational "AI threads".

  • You are always informed when you are interacting with an AI-generated summary or an AI assistant rather than a human.
  • AI processing of your email and calendar content is used solely to generate the output you requested (e.g. a summary, a suggested reply, a scheduling suggestion) and is not used to build advertising profiles.
  • Pingly does not make decisions producing legal or similarly significant effects about you based solely on automated processing, without the possibility of human review.

5. How long we keep your data

We retain personal data only for as long as necessary for the purposes described in this policy. Your account and personal data are kept for as long as your account is active, and are deleted within 90 days after your account is closed, unless a longer period is required by law.

6. Who we share your data with

We do not sell your personal data. We share data only with service providers ("sub-processors") who help us operate Pingly, under contractual data protection terms:

  • Google (Gmail API, OAuth) and Microsoft (Outlook/Graph API) — to retrieve mail and calendar data you have authorized.
  • Google Gemini — AI model provider used to generate summaries, suggestions, and AI thread responses.
  • Exa — search/data-retrieval API used to power certain AI features.
  • Supabase — database and caching infrastructure used to store account and application data.

7. International data transfers

All of our service providers (Google, Microsoft, Google Gemini, Exa, Supabase) process your data within the European Economic Area (EEA). We do not transfer your personal data outside the EEA. If this changes in the future, we will update this policy to describe the safeguards that apply, such as the European Commission's Standard Contractual Clauses.

8. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten"), including by deleting your account.
  • Restrict or object to certain processing.
  • Data portability, i.e. receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent, without affecting past lawfulness.
  • Lodge a complaint with a supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection, or the supervisory authority in your own EU member state.

To exercise any of these rights, contact us at anna@pingly.info. We will respond within one month as required by law.

9. Security

We apply appropriate technical and organizational measures — including encryption of data in transit, access controls, and OAuth token scoping — to protect your data against unauthorized access, loss, or misuse.

10. Children

Pingly is not directed at children under 16, and we do not knowingly collect personal data from children under that age.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified in-app or by email before they take effect.

12. Contact

If you have questions about this Privacy Policy or how we handle your data, contact us at anna@pingly.info.